Governance Risk and Compliance Analyst

Ice Miller LLP

Baltimore (MD)

On-site

USD 75,000 - 100,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Paid time off
401k with employer match
Vision and dental insurance

Job summary

Ice Miller LLP is seeking a GRC Analyst to leverage security policies, standards, and controls, consulting across the firm and informing on risk to systems and data. You will help ensure GRC functions are embedded in key programs and validate that risk mitigation is effective.

The position involves governance, risk, and compliance activities across HIPAA, PCI, ISO2700x, NIST frameworks, and audits, with a focus on improving security controls and awareness throughout the organization.

Qualifications

  • Understanding of HIPAA, Meaningful Use, PCI DSS, ISO2700x, FDA.
  • Understanding of ISO2700x, NIST CSF, NIST SP 800-53, HITRUST.
  • Familiarity with security auditing and risk assessment processes.
  • Skills in documenting risk and compliance activities.
  • Excellent written and verbal communication skills for technical and non-technical audiences.
  • Proficient in incident response playbooks and tabletop exercises.
  • Knowledge of cybersecurity risk management and governance.

Responsibilities

  • Develop and manage cyber security policies, standards, procedures and governance.
  • Assess platforms against security and configuration standards.
  • Interface with security personnel to align remediation with best practices.
  • Collaborate with IT to identify and address key cybersecurity risks.
  • Develop and deploy information security awareness, training and communications.
  • Evaluate exceptions to security policies and administer identity governance.
  • Support internal and external audits and responses to security questionnaires.
  • Provide guidance on regulatory impacts to management and stakeholders.

Skills

Regulatory compliance
Risk assessment
Information security governance
Policy development
Audit coordination

Education

Bachelor's degree in a related field

Job description

Job Summary:

As a GRC Analyst, your role on the team will include leveraging your knowledge of security policies, standards, controls, and industry best practices to consult with others in the firm and inform on risk to systems and data. You will be involved playing a critical role in ensuring that GRC functions are incorporated into key firm programs while validating risk mitigation functions are functioning correctly.

Salary in the range of $75,000 - $100,000 dependent on location and experience level
Essential Job Duties:
  • Governance
    • Support the development and management of cyber security policies, standards, procedures, and overall governance based on the NIST Cyber Security Framework, NIST 800-53, and CIS controls.
    • Assess current platforms against security and configuration standards
    • Interface with key security personnel to ensure expectations and remediation activities are aligned to best practices
    • Work closely with the IT team to ensure key cybersecurity risks and issues are identified, addressed, and resolved in a timely manner.
    • Assist in the development and deployment of information security awareness, training, and communication capabilities as it relates to governance changes.
    • Evaluate and process exceptions to information security policies and standards
    • Assist with the administration of identity governance and administration activities
    • Receive audit findings, legal obligations, compliance, and regulatory requirements as input to policy development.
    • Manage lateral transfers of data in and out of the firm and implement ethical walls
  • Risk
    • Measure and monitor cybersecurity risk.
    • Manage and prioritize the risk exception queue
    • Perform risk assessments in alignment with methodologies and provide timely feedback to stakeholders
    • Assist in conducting a business impact analysis for business systems, applications, and processes
    • Assist with the development of cyber resilience plans including incident response, business continuity, and disaster recovery
    • Participate in Third Party Risk Management Program activities
  • Compliance
    • Maintain awareness of existing and proposed security standards, state and federal legislations and regulations pertaining to information security.
    • Identify regulatory changes that will affect information security policy, standards, and procedures, and recommend appropriate changes.
    • Participate in internal and external compliance audits and security questionnaire responses.
    • Provide guidance to management and business stakeholders regarding the security impact of regulations, policies, applicable laws, and key risks.
    • Participate in compliance reviews as assigned by management.
Minimum Requirements:
  • Understanding of common security regulations (e.g., HIPAA, Meaningful Use, PCI DSS, ISO2700x, FDA, etc.).
  • Understanding of common industry security frameworks (e.g., ISO2700x, NIST CSF, NIST SP 800-53, HITRUST, etc.).
  • Familiarity with security auditing and risk assessment processes.
  • Skills in documenting risk and compliance activities.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and non-technical audiences at various hierarchical levels.
  • Proficient in the development and delivery of incident response playbooks and tabletop exercises
  • Sound knowledge of business management and an expert knowledge of information/cybersecurity risk management and governance.
  • Experience responding to, analyzing, and communicating information security audits.
  • Basic understanding of general security concepts including but not limited to cryptography, DLP, Security Operations Center, Security Managed Services, SIEM, FW, Audit, Cloud Security, Mobile Security .
Other Expectations:
  • Strong ability to follow instructions, ask intelligent questions, and engage critical thinking skills to complete the work
  • Self-starter: ability to work independently with minimal supervision.
  • Ability to work effectively in a team environment.
  • Maturity to accept direction, confidence to give direction.
  • Ability to quickly identify risks that require escalation to higher levels of leadership
  • Ability to operate independently and show measurable progress daily
  • Ability to manage multiple tasks simultaneously without missing deadlines or dropping assignments
  • Ability to adapt quickly and without frustration to changing priorities and emphasis
  • Strong attention to detail and high commitment to quality
  • Good attitude and courtesy to work with a small, fast-paced team
  • Efficient worker looking for ways to gain efficiencies and maximize time spent
Other Requirements:

The requirements described below are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Equipment Operated:

This position requires extensive use of a computer and telephone. This position also requires the use of printing, copying, faxing and scanning equipment.

Physical Requirements:

While performing the duties of this job, the employee is occasionally required to sit; stand; talk; see; and hear.

Mental Requirements:

Ability to communicate effectively, verbally and in writing, with a diverse group of people.

Work Environment:

While performing the duties of this job, the employee may be exposed to weather conditions while traveling. The noise level in the work environment is usually moderate.

The above statements are intended to describe the general nature and level of work being performed in this position. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities from time to time. Nothing in this job description restricts management’s right to assign or reassign duties and responsibilities to this job at any time.

Benefits provided include:

Paid time off, Health insurance, Vision and Dental Insurance, 401k (with an employer match), life insurance, and many others. Please reach out for a comprehensive list of benefits provided.

Ice Miller is committed to recruiting, developing and retaining talented attorneys and professional staff from all backgrounds. To succeed, we take great pride in a culture where everyone at Ice Miller feels respected, is treated fairly and has the opportunity to perform to their highest potential.

Candidates must have permanent authorization to work in the United States.

Ice Miller LLP is an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance Analyst
Governance Risk and Compliance Analyst

Ice Miller LLP • Philadelphia

On-site
USD 75,000 - 100,000
Health insurance
Vision and Dental Insurance
401k (employer match)
+1
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Information Governance Records Analyst
Information Governance Records Analyst

Ice Miller LLP • Cleveland (OH)

On-site
USD 65,000 - 90,000
Paid time off
Health insurance
Vision and Dental Insurance
+1
Information Governance Records Analyst
Information Governance Records Analyst

Ice Miller LLP • Baltimore (MD)

On-site
USD 65,000 - 90,000
Paid time off
Health insurance
Vision and Dental Insurance
+2
Information Governance Records Analyst
Information Governance Records Analyst

Ice Miller LLP • Columbus (OH)

On-site
USD 65,000 - 90,000
Paid time off
Health insurance
Vision and Dental Insurance
+2
Information Governance Records Analyst
Information Governance Records Analyst

Ice Miller Llp • Indianapolis (IN)

On-site
USD 65,000 - 90,000
Paid time off
Health insurance
Vision and dental insurance
+1
Governance Risk & Compliance Analyst
Governance Risk & Compliance Analyst

System One • Denver (CO)

Hybrid
USD 80,000 - 100,000
Health and welfare benefits
401(k) plan
Medical, dental, and vision coverage
Information Governance Records Analyst
Information Governance Records Analyst

Ice Miller LLP • Philadelphia

On-site
USD 65,000 - 90,000
Paid time off
Health insurance
Vision and dental insurance
+2
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship